Back to Cybersecurity

Essential Eight for Government Suppliers: What Australian Agencies Expect From SaaS Vendors

Essential Eight for government suppliers illustration: bold flat geometric composition of eight shapes arranged in a grid leading to a government building silhouette

Short answer: The Essential Eight for government suppliers is not a universal legal mandate. The PSPF requires non-corporate Commonwealth entities to reach Maturity Level Two themselves, and agencies must manage supplier security risk through contracts. So SaaS vendors are often asked, contract by contract, to show a target maturity level, alongside IRAP or Hosting Certification where relevant.

Related guides:

Key takeaways

  • Under the Protective Security Policy Framework (PSPF), Maturity Level Two is the mandatory Essential Eight baseline for non-corporate Commonwealth entities, and has been since 1 July 2022.
  • That obligation sits on the agency, not on you. It reaches suppliers through procurement risk assessments and the security terms agencies write into contracts.
  • IRAP assessments against the Information Security Manual (ISM) and the Hosting Certification Framework (HCF) are separate schemes. Which one applies depends on what you host and at what classification.
  • For a cloud SaaS vendor, the Essential Eight fits your corporate IT more naturally than your product platform. Say so clearly and back the platform with mapped controls.
  • Prepare one evidence pack per target maturity level, then reuse it across every tender.

What does the PSPF require of Commonwealth entities?

The PSPF makes Essential Eight Maturity Level Two a mandatory baseline for non-corporate Commonwealth entities (NCEs), meaning most federal departments and agencies.

The Australian Signals Directorate's (ASD) Essential Eight maturity model FAQ states that for NCEs subject to the PSPF, "Maturity Level Two is considered a mandatory baseline". ASD's Commonwealth Cyber Security Posture in 2025 report confirms that since 1 July 2022 the PSPF has required entities to implement the Essential Eight to Maturity Level Two, and that the framework was relaunched as PSPF Release 2025 on 24 July 2025. The same report says Maturity Level Three is not mandated, though entities should consider whether their threat environment warrants it.

Two points as of October 2026:

  1. The obligation is on the entity. Nothing in these sources places the Essential Eight directly on private companies.
  2. The framework is evolving. In June 2026 ASD opened a consultation on the evolution of the Essential Eight, proposing a new "Essentials" series whose first chapter, "Essentials for enterprise IT", builds on the ISM. Treat any changes as proposed until ASD publishes final guidance.

Does the Essential Eight apply to government suppliers?

Not by default, but it often reaches you through the agency's procurement process and the contract you sign.

Flow diagram showing how Essential Eight expectations reach suppliers: the PSPF requires agencies to implement the Essential Eight, the agency assesses supplier security risk, the contract adds security terms, and the supplier evidences its controls

Agencies are accountable for the security risks that come with what they buy. The Australian National Audit Office's audit of cyber security supply chain risk management describes PSPF requirements that entities put proportionate protective security measures in place when procuring, include relevant security terms and conditions in contracts, and make sure contracted security controls are implemented and maintained over the contract's life. The same audit quotes Commonwealth Procurement Rule 8.3, which says entities should consider and manage procurement security risk, including cyber security risk.

In practice that creates a chain:

  1. The PSPF requires the agency to implement the Essential Eight.
  2. The agency assesses the security risk your service introduces.
  3. The contract adds security terms, which may name an Essential Eight maturity level.
  4. You evidence your controls during the tender and for the life of the contract.

ASD's FAQ acknowledges this pattern: it notes that an organisation contractually required to implement Maturity Level Two should follow those requirements. In our experience, the level requested varies by agency and data sensitivity, so read the tender and draft contract closely.

Which other assurance schemes will government buyers ask about?

Expect questions about IRAP and the Hosting Certification Framework, and recognise that each answers a different question from the Essential Eight.

Scheme What it is When it may come up (in our experience)
Essential Eight ASD's prioritised mitigation strategies, assessed against a maturity model Baseline security questions in many tenders
IRAP assessment An independent assessment by an ASD-endorsed assessor against applicable ISM controls Cloud services handling government data, especially higher sensitivity
Hosting Certification Framework Strategic, Assured or Uncertified status for hosting providers Hosting sensitive government data, whole-of-government systems or PROTECTED systems
ISO 27001 or SOC 2 Independent certification or attestation of your security program Common supporting evidence alongside the above

Key points from the primary sources:

  • IRAP is an assessment, not a certification. ASD's IRAP consumer guide says assessors identify applicable ISM controls and test them, and that a completed assessment "does not imply that a system is compliant, endorsed or approved by ASD". The buyer receives an IRAP assessment report to inform its own authorisation decision.
  • There is no ASD certified cloud list. ASD's cloud services page states the Certified Cloud Services List ceased on 27 July 2020.
  • The HCF targets hosting providers. The Hosting Certification Framework supports the PSPF and ISM and applies to hosting for sensitive government data, whole-of-government systems and PROTECTED systems. It currently covers data centre providers and cloud service providers. SaaS vendors may be asked which certification their hosting provider holds.

Holding ISO 27001 or a SOC 2 report does not replace an Essential Eight answer, but it gives evaluators independent evidence for many of the same controls.

What do state governments expect from suppliers?

States run their own policies, and NSW is a clear example of contract-level supplier requirements.

The NSW Cyber Security Policy 2026–2027 applies to NSW Government departments, public service agencies and statutory authorities. Its mandatory requirements embed the Maturity Level One Essential Eight controls, and agencies submit an annual assurance assessment by 31 October. On suppliers, it requires agencies to identify and manage third-party service provider risks, keep an inventory of ICT providers, have a contractually supported process for providers to notify incidents, monitor provider adherence, and include cyber security requirements and break clauses in contracts with third-party service providers.

Expect NSW buyers to ask about incident notification and contractual cyber clauses as well as your controls. Other states have their own frameworks, so check each jurisdiction you sell into.

How does the Essential Eight apply to a cloud SaaS product?

Apply it fully to your corporate IT, and be explicit about how you cover your product platform, because the Essential Eight was not designed primarily for cloud workloads.

Comparison diagram of where the Essential Eight lands for a SaaS vendor: corporate IT covers staff laptops and desktops, admin workstations, Office macros and browsers, and email and identity; the SaaS platform covers cloud admin consoles, production servers and containers, CI/CD and code repositories, and mapped controls plus ISM or ISO 27001

ASD's FAQ says the Essential Eight is "designed to protect organisations' internet-connected information technology networks" and, while it may be applied to other environments, "it was not designed for such purposes". Strategies such as restricting Microsoft Office macros map cleanly to staff laptops, less so to a containerised production platform.

A defensible scope for a SaaS or HealthTech vendor usually has two parts:

  • Corporate IT, assessed against the maturity model: staff laptops and desktops, administrator workstations, Office macros and browsers, email and your identity provider. This is where the eight strategies apply as written.
  • Product platform, covered by mapped controls: cloud admin consoles, production servers and containers, CI/CD pipelines and code repositories. Show the intent of each strategy (patching, MFA, restricted admin privileges, backups) with platform controls, and point to ISM-aligned or ISO 27001 evidence.

In our experience, evaluators look hardest at how privileged users reach production, so cover admin workstations and cloud console access with MFA and privilege restrictions in both halves of your scope.

How should a supplier prepare before tendering?

Self-assess against the maturity model, pick a target per buyer, and build an evidence pack before the tender lands.

Six-step supplier readiness plan: define scope, self-assess against the maturity model, set a target level per buyer, close gaps and record exceptions, build the evidence pack, and refresh before each tender

  1. Define scope. Write down which environments the assessment covers, using the corporate IT and product platform split above.
  2. Self-assess against the maturity model. Work through each strategy using ASD's Essential Eight assessment process guide as your method, and record the level you actually achieve, strategy by strategy.
  3. Set a target level per buyer. A federal agency bound by the PSPF may expect Maturity Level Two from systems that touch its environment, while an NSW agency's own baseline is Maturity Level One. Let the tender documents decide, not guesswork.
  4. Close gaps and record exceptions. Fix what you can; document compensating controls and dates for the rest.
  5. Build the evidence pack. Include the scope statement, a per-strategy maturity summary, policies, configuration exports, access reviews, patching reports and backup restore tests.
  6. Refresh before each tender. Evidence ages quickly, so rerun the self-assessment regularly.

How do you answer Essential Eight tender questions?

Answer per strategy, state your scope and level honestly, and attach evidence rather than adjectives.

Security schedules often ask "Do you comply with the Essential Eight?" A one-word "Yes" invites follow-ups and creates contractual risk if inaccurate. A stronger answer looks like this example:

"Our corporate environment was self-assessed against the ASD Essential Eight Maturity Model in [month, year]. We meet Maturity Level Two for six strategies and Maturity Level One for two, with remediation planned by [date]. Our cloud platform is outside the model's primary design scope, so we apply equivalent controls for patching, MFA, privileged access and backups, evidenced in the attached control mapping."

Checklist for every response:

  • Name the maturity model version and assessment date
  • State scope: corporate IT, product platform, or both
  • Give the level per strategy, not one blended score
  • Say whether the assessment was self-performed or independent
  • Note exceptions and remediation dates
  • Cross-reference IRAP, HCF, ISO 27001 or SOC 2 evidence where relevant
  • Confirm incident notification commitments if the buyer asks

A reviewed answer library speeds this up. See how to respond to enterprise security questionnaires fast.

How SecureSlate helps

SecureSlate helps vendors organise the work behind government tenders. The Essential Eight is set up as a custom framework, with custom controls for each strategy and maturity level, so you can track your self-assessment and evidence in one place. Multi-framework control mapping lets the same controls support ISO 27001, SOC 2, HIPAA and NIST CSF evidence. Agentless read-only cloud integrations and the device agent help collect evidence from your platform and staff devices, and access reviews support your privileged access story. Security questionnaire automation helps you answer tender security schedules consistently, the trust center shares your documentation with buyers, and audit management and risk management support independent assessments and exception tracking. SecureSlate does not perform IRAP assessments or certify maturity levels.

Start your free SecureSlate trial

FAQ

Is the Essential Eight mandatory for companies selling to the Australian government?

Not as a general law. The PSPF mandates Maturity Level Two for non-corporate Commonwealth entities themselves. A supplier becomes bound when a contract or tender requirement says so, which is common, so check each request for tender and draft contract.

What maturity level should a government supplier target?

Target whatever the buyer specifies. Commonwealth agencies work to a Maturity Level Two baseline, and the NSW policy embeds Maturity Level One controls for its agencies. If nothing is specified, document your current level per strategy and your roadmap.

Is an IRAP assessment the same as Essential Eight compliance?

No. An IRAP assessment is an independent assessment by an ASD-endorsed assessor against applicable ISM controls, and ASD says it does not mean a system is approved or certified. The Essential Eight is a smaller set of mitigation strategies assessed against a maturity model.

Does my cloud SaaS platform need to meet the Essential Eight?

ASD says the Essential Eight was designed for internet-connected IT networks, not other environments. Apply it to corporate IT, and cover your platform with mapped equivalent controls that you explain clearly in tender responses.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Keep reading

Oct 9, 2026 · Cybersecurity

CISA Secure by Design Pledge: Should Your SaaS Company Sign?

Oct 8, 2026 · Cybersecurity

Patch Management Compliance: Building a Patching Process Auditors Accept

Oct 7, 2026 · Cybersecurity

Cloud Migration Security: A Phase-by-Phase Checklist for SMBs

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?